Security Notes

  • The password is only posted to the API over HTTPS.
  • The JWT is stored in session storage, not local storage, and cleared on logout or expiry.
  • The page revalidates the token against a protected API endpoint before treating it as active.